Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1881 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.9) | 0.32% | — | Catalystconnect Catalyst Connect Zoho CRM Client PortalAI | 11/7/2026 | 29/9/2026 | The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’ parameter in all versions up to, and including, 2.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Aplazada | Alta (7.5) | 0.62% | — | Docuform Gmbh FSM ClientAI | 9/7/2026 | 10/7/2026 | An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability was identified in the authentication mechanism that allows user enumeration through the login interface. An attacker can differentiate between valid and invalid usernames… | |
| Aplazada | Alta (8.1) | 0.55% | — | Docuform ClientAI | 9/7/2026 | 10/7/2026 | A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code via the dfm-menu_report.php component. Attackers can exploit this flaw to read arbitrary files on the server, including sensitive configuration files, source code or system files. | |
| Aplazada | Alta (8.1) | 0.57% | — | Docuform Gmbh ClientAI | 9/7/2026 | 10/7/2026 | An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and report.php component | |
| Aplazada | Alta (8.1) | 0.68% | — | Docuform ClientAI | 9/7/2026 | 10/7/2026 | An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings component, and modify or retrieve sensitive data associated with other users’ accounts. | |
| Pendiente de análisis | Media (5) | 0.20% | — | Langsmith Client SDKAI | 6/7/2026 | 7/7/2026 | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can send an HTTP request to a server running the LangSmith SDK's TracingMiddleware can cause that server to read an arbitrary file from its local filesystem and upload the contents to LangSmith as a trace… | |
| Pendiente de análisis | Media (5.3) | 0.21% | — | Dell Client Platform BiosAI | 3/7/2026 | 7/7/2026 | Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure. | |
| Pendiente de análisis | Media (4) | 0.33% | — | AsynchttpclientAI | 1/7/2026 | 6/8/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In versions from 2.0.0 prior to 2.16.0 and from 3.0.0.Beta1 prior to 3.0.11, ThreadSafeCookieStore stored a cookie under the value of its Domain attribute without verifying that the… | |
| Aplazada | Media (6.4) | 0.07% | — | Catonetworks Cato ClientAI | 1/7/2026 | 2/7/2026 | Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before v.5.13.1 on macOS allows a local authenticated attacker to escalate privileges to root via a self-signed certificate that bypasses the XPC caller verification and a… | |
| Pendiente de análisis | Alta (7.5) | 0.41% | 💥 PoC | Safetica Endpoint ClientAI | 26/6/2026 | 26/6/2026 | Kernel driver ProcessMonitorDriver.sys in Safetica's endpoint client x64 , versions 10.5.75.0 and 11.11.4.0, allows unprivileged user to abuse IOCTL path and terminate protected system processes. | |
| Analizada | Media (5) | 0.25% | — | Jenkins GIT Client | 24/6/2026 | 26/6/2026 | Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, allowing attackers able to control the name of a build's working directory to execute arbitrary operating system commands on the agent. | |
| Aplazada | Alta (8.1) | 0.72% | 💥 PoC | Vmware CRMAIVmware Pivotal.core.common.dllAIVmware Pivotal.engine.client.services.conversion.dllAI | 23/6/2026 | 25/6/2026 | An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components. | |
| Aplazada | Crítica (9.1) | 0.57% | — | NET Statsite ClientAI | 22/6/2026 | 22/6/2026 | Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newlines are not removed from metric names, allowing metric injections. Values are not sanitised for newlines or other protocol control characters… | |
| Aplazada | Alta (7.3) | 0.18% | — | Papercut Print Deploy ClientAI | 22/6/2026 | 23/6/2026 | An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system utility using an… | |
| Aplazada | Crítica (9.3) | 0.41% | — | Traccar ClientAI | 17/6/2026 | 17/6/2026 | Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an attacker-controlled server. The app registers a… | |
| Aplazada | Media (6.5) | 0.44% | — | Control Panel Client Portal PROAI | 17/6/2026 | 17/6/2026 | CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions. | |
| Pendiente de análisis | Media (6.8) | 0.14% | — | Netskope ClientAI | 17/6/2026 | 30/9/2026 | — | |
| Pendiente de análisis | Media (6.8) | 0.16% | — | Netskope ClientAI | 17/6/2026 | 30/9/2026 | — | |
| Pendiente de análisis | Media (5.7) | 0.17% | — | Dell Client Platform BiosAI | 9/6/2026 | 23/7/2026 | Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Pendiente de análisis | Media (6.3) | 0.12% | — | Dell Inventory Collector ClientAI | 9/6/2026 | 23/7/2026 | Dell Inventory Collector Client, versions prior to 13.8.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write. | |
| Analizada | Alta (7.5) | 1.0% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Alta (7.5) | 0.61% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.5) | 0.61% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Modificada | Alta (8.8) | 0.82% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Modificada | Alta (7.5) | 0.47% | — | Microsoft Remote Desktop ClientMicrosoft Windows 11 23h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+3 | 9/6/2026 | 23/7/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |